All skills
garrytan avatar

/ship

@96764e8 official
by Garry Tangarrytan/gstack135k stars
20,051

Ship workflow: detect + merge base branch, run tests, review diff, bump VERSION, update CHANGELOG, commit, push, create PR. (gstack)

Use this Skill: https://skilld.dev/gh/garrytan/gstack/ship

This session only. Nothing lands on disk.

sectionsshared-code-reuse.md

≈586 tokens on demand. Your agent reads this file only when SKILL.md points to it.

<!-- AUTO-GENERATED from shared-code-reuse.md.tmpl — do not edit directly --> <!-- Regenerate: bun run gen:skill-docs -->

Reuse a skipped shared-code advisory only with complete structural evidence:

  1. Read the evidence. Read all supporting callers and the helper destination. Establish first-party authored provenance and whether the current extraction is worthwhile; the checker cannot decide that. Retain evidence_paths/helper_target.
  2. Run the checker. From the repository root, pass the current finding as literal JSON on stdin. Replace REVIEW_START with this pass's captured token and the example paths/symbol with actual evidence. Keep the quoted delimiter.
"$HOME/.claude/skills/gstack/bin/gstack-review-log" --check-shared-libs REVIEW_START <<'GSTACK_SHARED_LIBS_REUSE_JSON'
{"advisory":true,"severity":"INFORMATIONAL","evidence_paths":["src/caller-a.ts","src/caller-b.ts"],"helper_target":{"path":"src/shared.ts","symbol":"sharedHelper"}}
GSTACK_SHARED_LIBS_REUSE_JSON
  1. Act on its result. Read the JSON. Only reusable: true permits suppression. False, command failure or unreadable output requires fresh source review and a new decision, never suppression. Do not supply your own snapshot, prior record or coverage.
  2. Persist through the logger. The logger recomputes final coverage; never supply proof yourself. Real defects retain normal Fix-First handling independently.

What a reusable result proves (do not reconstruct these checks yourself):

  • Identity: sharedLibsFingerprint plus the actual repo, raw branch and current snapshot. The checker reads REVIEW_START without consuming/replacing it. Sanitized branch names are not identity.
  • Prior decision: completed/converged review, verified binding, explicit Skip and logger-versioned snapshot_covered_paths; older unversioned coverage needs a fresh decision.
  • Source: canReuseSharedLibsAdvisory requires every supporting path's raw file byte-for-byte with its blob. Exclude assume-unchanged, skip-worktree and sparse index entries; symlinks/ancestors, submodules, ignored/outside or unreadable files; active/unknown Git filters, encodings and line conversion.
  • Safe inspection: disables fsmonitor and optional locks; never uses external diff/textconv. Unknown evidence fails closed.

Source: SKILL.md on GitHub

1 alert3d4 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    The 'ship' skill is a highly sophisticated automation workflow for shipping code, including merging, testing, and PR creation. It features robust security mitigations like redaction scans and trust boundaries for subagents. The primary security considerations involve its inherent attack surface for indirect prompt injection—processing untrusted data like PR bodies and plan files—and the use of dynamic execution to generate and run tests at runtime. These are core functionalities for the skill's purpose and are accompanied by safety gates.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer6mo

    1/1 file flagged

Signed by skilld at 96764e8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 18 hours ago.

Activeupdated 2 days ago
What it can do
Runs commands Reads files Edits files Network
preamble-tier
4
version
1.0.0
triggers
[
  "ship it",
  "create a pr",
  "push to main",
  "deploy this"
]
All 9 allowed tools
BashReadWriteEditGrepGlobAgentAskUserQuestionWebSearch

README badge

README badge for garrytan/gstack/ship

Orchestrates a complete release workflow: detects the base branch, merges it, runs tests, reviews the diff, bumps VERSION, updates CHANGELOG, commits, pushes, and creates a pull request. Built on the gstack tool and triggered by phrases like "ship it" or "create a PR".

Generated from the current SKILL.md.

What does this skill do?
The ship skill automates the full release workflow: detect and merge the base branch, run tests, review the diff, bump VERSION, update CHANGELOG, commit, push, and create a PR. Invoke it when code is ready to ship.
When should I invoke this skill instead of pushing manually?
Invoke ship proactively whenever the user says code is ready, asks to deploy, wants to push code up, or requests creating a PR. Do not push or create a PR directly — the skill handles the entire workflow.
What tools and permissions does this skill use?
The skill uses Bash, Read, Write, Edit, Grep, Glob, Agent, AskUserQuestion, and WebSearch. It requires git access and permission to commit, push, and create pull requests.
Does this skill work in plan mode?
Yes. In plan mode, treat the skill file as executable instructions and follow it step-by-step. The first AskUserQuestion call satisfies plan mode's end-of-turn requirement. Do not call ExitPlanMode until the workflow completes.

Generated from the current SKILL.md. These answers refresh after source changes.